🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A financial services firm is implementing an email-based approval workflow for large wire transfers. Security policy mandates that the originator of each approval must not be able to later deny having sent it, and that auditors must be able to validate both the sender's identity and the message integrity months later. Which control BEST satisfies this non-repudiation requirement?

  • Record only a SHA-256 hash of each approval email in a secure, tamper-evident log.

  • Rely on the SMTP server's timestamp headers to prove when the approval message was sent.

  • Encrypt each approval email using a unique symmetric session key shared between the sender and the finance team.

  • Digitally sign each approval email with the sender's private key and make the matching public key available for verification.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot